<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
<TITLE>How to Choose a Password</TITLE>
</HEAD>

<BODY BGCOLOR="#FFFFFF" TEXT="#000000">

<OBJECT TYPE="application/x-oleobject" CLASSID="clsid:1e2a7bd0-dab9-11d0-b93a-00c04fc99f9e">
	<PARAM NAME="Keyword" VALUE="choose">
</OBJECT>

<P><A NAME="hid_choose_password"></A><A NAME="id_help_choose"></A><B>How To Choose a Password...</B></P>

<P>Your passwords are the keys to many computers, from a bank machine to a multiuser mainframe to a server on a network. Your password helps to prove that you are who you say you are, and ensures your privacy.</P>

<P>Compromised passwords are the means by which most unauthorized (and unscrupulous) people gain access to a system. Someone logging on under your name has access not only to your computer files, but to most of the facilities of the computer system. Since tampering can have far-reaching and serious consequences, it's important to take to heart the following guidelines for choosing a password.</P>

<P><B>Do choose</B>:</P>

<P>*Something easy for you to remember with at least six characters.</P>

<P>*Something obscure. For instance, you might deliberately misspell a term or use an odd character in an otherwise familiar term, such as "phnybon" instead of "funnybone." Or use a combination of two unrelated words or a combination of letters and numbers.</P>

<P>*A combination of letters and numbers, or a phrase like "many colors" and then use only the consonants "mnYc0l0rz."</P>

<P>*An acronym for your favorite saying, for example, "L!isn!" (Live! It's Saturday Night!)</P>

<P><B>Don't choose</B>:</P>

<P>*Your name in any form - first, middle, last, maiden, spelled backwards, nickname or initials.</P>

<P>*Your userid, or your userid spelled backwards.</P>

<P>*Part of your userid or name.</P>

<P>*Any common name, such as Joe.</P>

<P>*The name of a close relative, friend, or pet.</P>

<P>*Your phone or office number, address, birthday, or anniversary.</P>

<P>*Your license-plate number, your social-security number, or any all numeral password.</P>

<P>*Names from popular culture, e.g., spock, sleepy. </P>

<P>*Any word in a dictionary.</P>

<P>*Passwords of fewer than four characters.</P>

<P><B>Mum's the Word</B></P>

<P>Never tell anyone your password -- not even your system administrator or account manager -- and don't write it down. Make sure you have chosen a password that you can remember. And, finally, change your password at regular intervals</P>

<P>Reprinted from i/s, Vol. 4, No. 9,</P>

<P>May 1989. Revised March 1993.</P>

<P>Copyright C 1993 MIT Information Systems</P>

<P>Send comments or questions about this publication to</P>

<P>&lt;comment-ispubs@mit.edu&gt; or call x3-5150</P>

<P>Before You Begin...</P>

<P>Remember that <I>passwords are case-sensitive, </I>and<I> </I>note whether your keyboard has Caps Lock on.<B> </B>Leash is<B> </B>not programmed to inform you about the state of your Caps Lock key.</P>

<P><B>How To Use Change Password...</B></P>

<P><B>1.</B>In Leash, click on the Change Password button (the one that says abc and has a green arrow), type your username in the first field of the dialogue box that opens, and press Enter or click OK. You may start over anytime by clicking Restart, stop at any time by clicking Cancel, or get help at any time with the Help button.</P>

<P><B>2.</B>Type your <I>current</I> password in the second field and press Enter or click OK.</P>

<P>The program checks the username and password you entered and notifies you if either is invalid.</P>

<P><B>3.</B>Type your <I>new</I> password in the third field and press Enter or click OK.</P>

<P><B>4</B>.Retype your <I>new</I> password, to verify it, and press Enter or click OK.</P>

<P>Once you have entered the new password twice with consistent spellings, the Leash program replaces your old password with the new, <I>if it is a strong password. </I>If Kerberos determines the password is weak, a message notifies you, and you need to<I> </I>repeat steps 1 through 4 with a strong password, as described by the "How To Choose a Password" guidelines above.</P>

<P><B>How Change Password Works...</B></P>

<P>When you type into the password fields of the dialog box, neither characters nor sounds echo back, thus keeping secret even the number of password characters. The program accepts only printable characters for new passwords, i.e., characters between ASCII codes 0x20 and 0x7E.</P>

<P>When you have entered the new password twice consistently, the program attempts to change the password via a dialogue with the Kerberos administrative server. Some Kerberos sites, including MIT's Athena environment, check the password's strength before allowing the change to take place and notifies you if it determines that the password is weak.</P>

</BODY>
</HTML>
